CyberRota Analysis
AI-GeneratedDevolutions Server versions up to 2026.3.5.0 are vulnerable due to the cleartext storage of sensitive information in the database, allowing attackers with read access to extract external identity provider tokens and active session identifiers. This exposure can lead to unauthorized access to user accounts and systems. Organizations using affected versions should prioritize remediation to protect sensitive data and prevent potential breaches.
Original NVD Description
Cleartext storage of sensitive information in the database in Devolutions ServerĀ 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.